vciy

CVEs we hold for Broadcom

Records whose assigning authority named Broadcom as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8370Automic Automation Agent Unix privilege escalationBroadcom Automic Automation
CVE-2026-3991Elevation of Privileges in Symantec Data Loss Prevention Windows EndpointBroadcom Data Loss Prevention
CVE-2026-3862Cross-Site Scripting Vulnerability in SiteMinder Administrative UIBroadcom SiteMinder
CVE-2026-15380Local privilege escalation in Symantec ITMSBroadcom Symantec Management Suite
CVE-2026-15379Arbitrary File Read as SYSTEM in Symantec ITMSBroadcom Symantec IT Management Suite
CVE-2026-11815Insecure Deserialization via MITM in Layer 7 Policy ManagerBroadcom Layer 7 API Gateway
CVE-2026-11626Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal ToolBroadcom Symantec Endpoint Protection CleanWipe Removal Tool
CVE-2025-9059Elevation of Privileges Vulnerability in IT Management SuiteBroadcom 8.6.IT Management Suite
CVE-2025-8661Stored Cross-Site Scripting in Symantec PGP Encryption 11.0.1Broadcom Symantec PGP Encryption
CVE-2025-8660Privilege Escalation in Symantec PGP Encryption 11.0.1Broadcom Symantec PGP Encryption
CVE-2025-7398Medium Strength Cipher Suites detected on port on ports 9000 and 8036Broadcom Brocade ASCG
CVE-2025-7397CLI history displays inline passwordsBroadcom Brocade ASCG
CVE-2025-69276Spectrum insecure deserialiationBroadcom DX NetOps Spectrum
CVE-2025-69275Spectrum outdated java library in class-pathBroadcom DX NetOps Spectrum
CVE-2025-69274Spectrum broken authorization schemeBroadcom DX NetOps Spectrum
CVE-2025-69273Spectrum broken authenticationBroadcom DX NetOps Spectrum
CVE-2025-69272Spectrum password returned in clearBroadcom DX NetOps Spectrum
CVE-2025-69271Spectrum basic authentication in useBroadcom DX NetOps Spectrum
CVE-2025-69270Spectrum session token in URLBroadcom DX NetOps Spectrum
CVE-2025-69269Spectrum command injection in NCM serviceBroadcom DX NetOps Spectrum
CVE-2025-69268Spectrum reflected XSSBroadcom DX NetOps Spectrum
CVE-2025-69267Spectrum directory path traversalBroadcom DX NetOps Spectrum
CVE-2025-6392Daily Data Dump Collector logs database password in cleartext when running docker exec commands (CVE-2025-6392)Broadcom Brocade SANnav
CVE-2025-6391JSON Web Token (JWT) Exposure in Log FilesBroadcom Brocade ASCG
CVE-2025-6390Cleartext storage of sensitive information in Brocade SANnav server audit logs.Broadcom Brocade SANnav
CVE-2025-5333Unauthenticated Remote Code Execution in IT Management SuiteBroadcom Symantec IT Management Suite
CVE-2025-4971Broadcom Automic Automation Agent Unix privilege escalationBroadcom Automic Automation
CVE-2025-4663Denial-of-Service (DoS) after Unusual or Exceptional Conditions vulnerabilityBroadcom Brocade Fabric OS
CVE-2025-4662Plaintext security passwords are logged in the audit logs while executing openssl cmdBroadcom Brocade SANnav
CVE-2025-36553Dell ControlVault3 CvManager buffer overflow vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-36463Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-36462Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-36461Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-36460Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-32089Dell ControlVault3 CvManager_SBI buffer overflow vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-31649Dell ControlVault3 ControlVault WBDI Driver hard-coded password vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-31361Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter privilege escalation vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-25215Dell ControlVault3/ControlVault3 Plus cv_close arbitrary free vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-25050Dell ControlVault3/ControlVault3 Plus cv_upgrade_sensor_firmware out-of-bounds write vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-24922Dell ControlVault3/ControlVault3 Plus securebio_identify stack-based buffer overflow vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-24919Dell ControlVault3/ControlVault3 Plus deserialization of untrusted input vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-24508Offline Extraction of Account Connectivity Credentials (ACCs) in IT Management SuiteBroadcom Symantec IT Management Suite
CVE-2025-24507no title heldBroadcom Symantec Privileged Access Management
CVE-2025-24506no title heldBroadcom Symantec Privileged Access Management
CVE-2025-24505no title heldBroadcom Symantec Privileged Access Management
CVE-2025-24504no title heldBroadcom Symantec Privileged Access Management
CVE-2025-24503no title heldBroadcom Symantec Privileged Access Management
CVE-2025-24502no title heldBroadcom Symantec Privileged Access Management
CVE-2025-24501no title heldBroadcom Symantec Privileged Access Management
CVE-2025-24500no title heldBroadcom Symantec Privileged Access Management
CVE-2025-24311Dell ControlVault3/ControlVault3 Plus cv_send_blockdata out-of-bounds read vulnerabilityBroadcom BCM5820X; Dell ControlVault3; Dell ControlVault3…
CVE-2025-13919Component Object Model (COM) Hijacking in Symantec Endpoint Protection Windows ClientBroadcom Symantec Endpoint Protection Windows Client
CVE-2025-13918Elevation of Privileges in Symantec Endpoint Protection Windows ClientBroadcom Symantec Endpoint Protection Windows Client
CVE-2025-13917Elevation of Privileges in Web Security Services (WSS) AgentBroadcom Symantec Web Security Services Agent
CVE-2025-10847DX UIM Probe Improper ACL Handling RCEBroadcom Unified Infrastructure Management
CVE-2024-38499Improper Privilege Management Vulnerability in CA Client Automation 14.5Broadcom CA Client Automation (ITCM)
CVE-2024-38496Symantec Privileged Access Manager Insecure Direct Object Reference vulnerabilityBroadcom Symantec Privileged Access Management
CVE-2024-38495Symantec Privileged Access Manager User Enumeration vulnerabilityBroadcom Symantec Privileged Access Management
CVE-2024-38494Symantec Privileged Access Manager Remote Command Execution vulnerabilityBroadcom Symantec Privileged Access Management
CVE-2024-38493Symantec Privileged Access Manager Reflected Cross Site Scripting vulnerabilityBroadcom Symantec Privileged Access Management
CVE-2024-38492Symantec Privileged Access Manager Remote Command Execution vulnerabilityBroadcom Symantec Privileged Access Management
CVE-2024-38491Symantec Privileged Access Manager SQL Injection vulnerabilityBroadcom Symantec Privileged Access Management
CVE-2024-36459Cross-Site Scripting Vulnerability in Symantec SiteMinder Web AgentBroadcom Symantec SiteMinder
CVE-2024-36458Symantec Privileged Access Manager Privilege Escalation vulnerabilityBroadcom Symantec Privileged Access Management
CVE-2024-36457Symantec Privileged Access Manager Authentication Bypass vulnerabilityBroadcom Symantec Privileged Access Management
CVE-2024-36456Symantec Privileged Access Manager Remote Command Execution vulnerabilityBroadcom Symantec Privileged Access Management
CVE-2024-36455Symantec Privileged Access Manager Remote Command Execution vulnerabilityBroadcom Symantec Privileged Access Management
CVE-2023-4345Broadcom RAID Controller web interface is vulnerable client-side control bypassBroadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4344Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4343Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4342Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4341Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUIBroadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4340Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log fileBroadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4339Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4338Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4337Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4336Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4335Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on LinuxBroadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4334Broadcom RAID Controller Web server (nginx) is serving private files without any authenticationBroadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4333Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by serverBroadcom LSI Storage Authority (LSA)
CVE-2023-4332Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log fileBroadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4331Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4329Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4328Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption…Broadcom LSI Storage Authority (LSA)
CVE-2023-4327Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are…Broadcom LSI Storage Authority (LSA)
CVE-2023-4326Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4325Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilitiesBroadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4324Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy…Broadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2023-4323Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setupBroadcom LSI Storage Authority (LSA); Intel RAID Web…
CVE-2019-9503Broadcom brcmfmac driver is vulnerable to a frame validation bypassBroadcom brcmfmac WiFi driver
CVE-2019-9502Broadcom wl driver is vulnerable to heap buffer overflowBroadcom WiFi drivers
CVE-2019-9501Broadcom wl driver is vulnerable to heap buffer overflowBroadcom WiFi drivers
CVE-2019-9500Broadcom brcmfmac driver is vulnerable to a heap buffer overflowBroadcom brcmfmac WiFi driver

93 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.